Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 502 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 502
Topic #: 1
[All PCNSE Questions]

A consultant deploys a PAN-OS 11.0 VM-Series firewall with the Web Proxy feature in Transparent Proxy mode.

Which three elements must be in place before a transparent web proxy can function? (Choose three.)

  • A. User-ID for the proxy zone
  • B. DNS Security license
  • C. Prisma Access explicit proxy license
  • D. Cortex Data Lake license
  • E. Authentication Policy Rule set to default-web-form
Show Suggested Answer Hide Answer
Suggested Answer: ACD 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
dgonz
Highly Voted 7 months ago
answers should be: - loopback interface, - User-ID configuration in the proxy zone (A) - specific Destination NAT (DNAT) rules
upvoted 5 times
...
hcir
Most Recent 1 month ago
the question does not make sense, there must be a mistake. user-id is not necessary, it is optional. DNS security license is optional too. Prisma Access Explicit Proxy, well, it is for explicit proxy. CDL? loool And there is no authentication for Transparent Proxy.
upvoted 1 times
...
Pacheco
2 months ago
ACD. I think some people are confusing Web Proxy with DNS proxy A. Required as stated here in the summary at the top > https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/web-proxy B. Why not B? DNS sec is used for DNS sinkhole in threat prevention. It can be used in conjunction with other stuff like web proxy, but is not required for the latter to work >> https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/dns-security/about-dns-security C. The web proxy feature is part of the Prisma Access product suite, and although I can't find extensive references to a transp proxy license, it's the first config step on this doc to activate it > https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/dns/configure-a-web-proxy/configure-transparent-proxy D. Prisma Access logging relies on CDL, so you need that license too, but I guess it's only required if you want logging. E. Not related
upvoted 1 times
...
electro165
7 months, 2 weeks ago
Selected Answer: ABE
A. User-ID for the proxy zone: User-ID is essential to associate user identities with their web traffic. This helps in enforcing user-based policies and allows the firewall to track user activities for web proxy functions. B. DNS Security license: A DNS Security license is required to inspect and enforce policies related to DNS traffic. This is an important component of transparent web proxy functionality as it allows the firewall to filter and control DNS requests made by users. E. Authentication Policy Rule set to default-web-form: An Authentication Policy Rule set to the "default-web-form" allows the firewall to handle authentication for users accessing the internet through the transparent web proxy. It is essential for user identification and tracking.
upvoted 2 times
VenomX51
3 days, 18 hours ago
E is not needed for Transparent proxy: "Transparent proxy is transparent to the user without requiring additional authentication"
upvoted 1 times
...
tamaster22
3 months, 1 week ago
C is for Prisma Access, not PAN-OS Proxy
upvoted 1 times
...
...
Betty2022
8 months, 2 weeks ago
Selected Answer: ABC
https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/web-proxy#id3d1ea0dd-360f-44ee-8c48-30678c80d509_id2b5c6385-2ec6-4ba8-b1f1-2bea8b5139f5 > (answer C)Configure Explicit Proxy or Configure Transparent Proxy If you have not already done so, activate the license for web proxy. >(answer A) For the transparent proxy method:User-ID configuration in the proxy zone >(answer B) Set up the DNS proxy for Transparent Proxy. X(not D) With transparent proxy, the client browser is not aware of the proxy. Transparent proxy supports inline mode deployment and does not support web cache communication protocol (WCCP). Transparent proxy is transparent to the user without requiring additional authentication. My own understanding: The real exam question could list answers: loopback interface, Destination NAT (DNAT), so keep an lookout for these as well.We know we need license, and user id in proxy zone as per A and C
upvoted 1 times
...
dgonz
8 months, 4 weeks ago
Selected Answer: ABC
should be ABC
upvoted 1 times
...
kinho1985
9 months, 4 weeks ago
the correct choices are A. User-ID for the proxy zone, B. DNS Security license, and E. Authentication Policy Rule set to default-web-form.
upvoted 1 times
[Removed]
9 months, 3 weeks ago
link to how you came about that? Why E and no C?
upvoted 1 times
...
...
ConfuzedOne
10 months, 2 weeks ago
@lgkhan - are you sure the Q is written / documented correctly? The link: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/web-proxy Shows answers C and D for Explicit Proxy, not Transparent Proxy. The only actual documented requirement for TRANSPARENT Proxy from that link, among the answers provided here, is A.
upvoted 2 times
...
Knowledge33
11 months, 1 week ago
Selected Answer: ABC
ABC is the correct answer.
upvoted 1 times
...
Selected Answer: ABC
A. User-ID for the proxy zone >> is correct for Transparent B. DNS Security license >> DNS proxy C. Prisma Access explicit proxy license >> same license for explicit and transparent Doesn't seem like a great question but D and E are definitely not correct. Transparent mode does not need addiontional authentication and CDL has nothing to do with web proxy.
upvoted 4 times
Pacheco
2 months ago
Web Proxy comes from Prisma Access, which uses CDL for logging specifically.
upvoted 1 times
...
...
jhoncena
1 year ago
A. User-ID for the proxy zone >> is correct for Transparent B. DNS Security license >> can`t see why !! C. Prisma Access explicit proxy license >> for Explicit not transparent D. Cortex Data Lake license >> not related E. Authentication Policy Rule set to default-web-form >> not related no idea !!
upvoted 1 times
...
duckduckgooo
1 year ago
I don't know.... For the transparent proxy method, the request contains the destination IP address of the web server and the proxy transparently intercepts the client request (either by being in-line or by traffic steering). There is no client configuration and Panorama is optional. Transparent proxy requires a loopback interface, User-ID configuration in the proxy zone, and specific Destination NAT (DNAT) rules. Transparent proxy does not support X-Authenticated Users (XAU) or Web Cache Communications Protocol (WCCP).
upvoted 1 times
...
BryanSalazar
1 year ago
Selected Answer: ABC
The correct answers are ABC
upvoted 1 times
...
lgkhan
1 year, 1 month ago
A,C,D https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/web-proxy
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...